GHSA-f45q-w629-wr25
## Impact The built-in async and blocking clients used reqwest's default redirect policy. `BaseUrl` constrains the initial request to the configured origin and path prefix, but redirect processing occurs after that validation. reqwest retains sensitive headers when a redirect changes only the path on the same scheme, host, and port. A redirect from a Hubuum endpoint to another path on a shared origin could therefore carry the bearer `Authorization` header outside the configured Hubuum path prefix. Exploitation requires an attacker, compromised server, or intermediary to influence a 3xx response. Cross-origin redirects are not affected because reqwest strips sensitive headers when scheme, host, or port changes. ## Patches Version 0.6.1 configures both built-in HTTP clients with `reqwest::redirect::Policy::none()`. Redirect responses are returned as 3xx API errors instead of being followed. Supplying a preconfigured reqwest client remains an explicit opt-in to that client's redirect policy. ## Workarounds On affected versions, construct a reqwest client with `reqwest::redirect::Policy::none()` and pass it through `with_http_client`. Deployments can also reduce exposure by ensuring the Hubuum origin is not shared with other applications and that trusted infrastructure never redirects API requests outside the configured path prefix.
Properties
- ghsa_id
- GHSA-f45q-w629-wr25
- severity
- medium
- summary
- Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects
- cve_id
- GHSA-f45q-w629-wr25
- is_ghsa_only
- true
- ghsa_published
- 2026-07-24T21:48:36Z
- source_url
- https://github.com/advisories/GHSA-f45q-w629-wr25
- ghsa_updated
- 2026-07-24T21:48:39Z
Related Entities (4)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph